Junglewise Threat Intelligence

CVE-1999-0537: Microsoft Internet Explorer and Netscape Navigator insecure active content execution

CVE-1999-0537 · Severity: high · CVSS 7.5 · Published 1998-04-01

Technologies: Netscape Navigator, Microsoft Internet Explorer. Vendors: Netscape, Microsoft.

Executive brief

A configuration issue in early web browsers like Internet Explorer and Netscape Navigator allows the automatic execution of active content such as ActiveX, Java, and JavaScript. This could allow malicious websites to run unauthorized code on a user's computer, potentially leading to data theft or system compromise. Organizations should ensure that browser security settings are configured to restrict or prompt for the execution of untrusted active content.

Technical details

This vulnerability stems from insecure default configurations or user-defined settings in legacy web browsers that permit the automatic execution of active content. By hosting malicious ActiveX controls, Java applets, or JavaScript on a webpage, an attacker can achieve remote code execution or unauthorized data access when a user visits the site. The attack vector is network-based and requires no prior authentication, relying on the browser's failure to sandbox or restrict these technologies effectively. Modern mitigations involve disabling legacy technologies like ActiveX and implementing strict Content Security Policies (CSP).

Affected products

  • Microsoft Internet Explorer
  • Netscape Netscape Navigator

Timeline

  • 1998-04-01: disclosed

References

Related threats